RHSA-2025:8274: Important: Errata Advisory for Red Hat OpenShift GitOps v1.14.4 security update
Errata Advisory for Red Hat OpenShift GitOps v1.14.4 security release.Security Fix(es): openshift-gitops-argocd-container: Improper URL Sanitization in Argo CD Repository Page Allows Cross-Site Scripting (XSS) gitops-1.14 openshift-gitops-1/gitops-operator-bundle: Improper URL Sanitization in Argo CD Repository Page Allows Cross-Site Scripting (XSS) gitops-1.14 openshift-gitops-1/argocd-rhel9: Improper URL Sanitization in Argo CD Repository Page Allows Cross-Site Scripting (XSS) gitops-1.14 openshift-gitops-operator-container: Namespace Isolation Break gitops-1.14 openshift-gitops-dex-container: Unexpected memory consumption during token parsing in golang.org/x/oauth2 gitops-1.14 openshift-gitops-container: Potential denial of service in golang.org/x/crypto gitops-1.14 openshift-gitops-argo-rollouts-container: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS gitops-1.14 openshift-gitops-argocd-container: jwt-go allows excessive memory allocation during header parsing gitops-1.14 openshift-gitops-argocd-rhel9-container: jwt-go allows excessive memory allocation during header parsing gitops-1.14 openshift-gitops-argocd-container: Prototype Pollution in redoc gitops-1.14 openshift-gitops-argocd-rhel9-container: Prototype Pollution in redoc gitops-1.14
Other sources
Important: Errata Advisory for Red Hat OpenShift GitOps v1.14.4 security update
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:8274?
The severity of RHSA-2025:8274 is classified as important.
How do I fix RHSA-2025:8274?
To address RHSA-2025:8274, you should update to the latest version of Red Hat OpenShift GitOps provided in the advisory.
What vulnerabilities are addressed in RHSA-2025:8274?
RHSA-2025:8274 addresses an improper URL sanitization vulnerability in Argo CD that allows for potential Cross-Site Scripting (XSS) attacks.
Which versions of Red Hat OpenShift GitOps are affected by RHSA-2025:8274?
All versions of Red Hat OpenShift GitOps prior to the security release v1.14.4 are affected by RHSA-2025:8274.
What is the impact of the vulnerability in RHSA-2025:8274?
The impact of the vulnerability in RHSA-2025:8274 is the potential for attackers to execute malicious scripts in the context of users in the Argo CD Repository Page.